UZCERT Warns of Widespread Cyberattacks Targeting RDP
Tashkent, Uzbekistan (UzDaily.uz) — UZCERT, the incident response service of Uzbekistan's Cybersecurity Center, has warned government agencies and businesses about widespread cyberattacks aimed at gaining unauthorized access to computers and servers through the Remote Desktop Protocol (RDP). The warning was issued by UZCERT of the Cybersecurity Center of Uzbekistan.
According to UZCERT, monitoring identified a large number of attack attempts, as well as several foreign IP addresses associated with malicious command-and-control (C2) infrastructure used to manage the cyberattacks.
A preliminary analysis showed that the attacks compromised the information systems of several organizations. On some computers and servers, attackers encrypted data. Specialists are continuing to investigate and analyze the identified incidents.
UZCERT recommended that government agencies and businesses assess the security of their information systems. If remote access via RDP is not required, organizations are advised to temporarily disable the service or block direct internet access to it.
Cybersecurity specialists were also advised to change passwords for administrator and user accounts with remote access privileges and to enable multi-factor authentication.
In addition, organizations are advised to review security event logs for suspicious connections, network activity and other signs of possible compromise. They should also examine servers and workstations with remote access for unauthorized connections, unknown user accounts and other suspicious changes.
If signs of compromise are detected, UZCERT recommends immediately disconnecting the affected computer or server from the network to prevent further spread of the attack and preserve evidence needed for the investigation.